🚨 New conference alert 🚨
Join us for RooCon, a free one-day conference on cyber threat intelligence and attribution.
The conference will be held at Google's offices in Sydney, Australia on Tuesday, 21st of November 2023.
Alternate hypothesis: independent developer who specializes in security impairment tools sells them to multiple actors like ELBRUS/FIN7 & DEV-0506 (Black Basta deployer)
Overlap in custom packer could be explained by ELBRUS “crypting” their malware/tools
https://t.co/IViuRPr7YO
Do you sit at a computer for longer than 6 hours a day?
You’re destroying your body if so.
Here’s the setup you need to protect yourself from posture problems and crippling long-term injuries:
🧵
Don't miss the next installment of the Mandiant FLARE team's webinar series, The Sample. This week, Principal Reverse Engineer Blaine Stancill will explain the inner workings of a dropper from the #WHITEDAGGER malware family. Register now! https://t.co/ocDKpqnOLA
When you don't yet have initial intrusion vector, avoid the temptation to assume insider/0day. Follow the evidence and prove it.
"It is a capital mistake to theorize before one has data. Insensibly one begins to twist facts to suit theories, instead of theories to suit facts"
Additional Command and Control IP's:
80.66.88[.]155
5.39.222[.]150
141.105.64[.]121
31.192.105[.]28
91.245.253[.]112
23.106.123[.]119
Timely blog @proofpoint team